← Back to Asitra

Your life data stays under your control.

This policy explains what Asitra processes, why it is needed, and the choices available to you. Effective 3 August 2026.

Who is responsible

Asitra is the data controller for the web service. Privacy enquiries and rights requests can be sent to ganatra.dev@gmail.com.

Information we process

Account identity comes from Google or Apple: an account identifier, name, email address, verification state and optional profile picture. Asitra stores the records you choose to add, including timeline and journal entries, lists, trackers, financial organization data, settings, consent history, shared-list membership, pictures, PDFs and voice notes. Security records can include session identifiers, timestamps, IP address, browser information and rate-limit counters.

Purposes and legal bases

Storage and service providers

Structured records are held in Cloudflare D1 and uploaded files in private Cloudflare R2 storage. Cloudflare also delivers the application and applies network protections. When AI is enabled, the question and a limited, relevant selection of account records are sent from Asitra’s server to OpenAI. The OpenAI API key is never sent to your browser. Asitra requests no-store model processing. Google and Apple process sign-in under their own privacy terms.

Retention, recovery and deletion

Current account data remains while your account is active. Asitra keeps up to 20 automatic state recovery points. Expired sessions, verification records and rate-limit counters are operational records and are periodically eligible for cleanup. Choosing Delete my data removes your private structured records, recovery copies, provider sessions and uploaded objects; shared content owned by another person is removed from your membership. A short-lived infrastructure backup can persist until its normal rotation completes.

Your controls and rights

Settings lets you download a machine-readable copy, withdraw AI consent, sign out and delete your data. Depending on your location, you may also request access, correction, erasure, restriction, portability, objection or withdrawal of consent, and complain to your local data-protection authority. Contact us if an in-app control does not cover your request.

Cookies, transfers and children

Asitra uses secure, HTTP-only cookies only for authentication and essential protection; advertising cookies are not used. Some providers may process information outside the European Economic Area using their applicable transfer safeguards. Asitra is not intended for children under 16 without authorization from a parent or guardian.

Changes

Material policy changes will be shown in the application with a new policy version. A new consent will be requested when a consent-based purpose changes materially.